Security Advisory

CVE-2026-10551

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-13 06:00:01
Last updated 2026-07-13 15:54:20
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.